<?php
session_start();
error_reporting(E_ALL);
include(dirname(__DIR__).'/functions.php');  
// Define a destination
$targetDir = realpath(dirname(__DIR__)).'\MC_DATA'; // Relative to the root

$targetFolder = str_replace('\\', '/', $targetDir);

//echo $targetFolder ;


if(isset($_POST['type']) && $_POST['type'] == 'photoidcheck')
{								  
	$verifyToken = md5('unique_salt' . $_POST['timestamp']);

	if (!empty($_FILES) && $_POST['token'] == $verifyToken) {
		$tempFile = $_FILES['Filedata']['tmp_name'];
		$targetPath = $_SERVER['DOCUMENT_ROOT'] . $targetFolder;
		$targetFile = rtrim($targetPath,'/') . '/' . $_FILES['Filedata']['name'];
		
		// Validate the file type
		
		$fileParts = pathinfo($_FILES['Filedata']['name']);
		
		
		/* ********** */
		
		$sql = "SELECT FirstName, SurName FROM crm_contact WHERE ContactID = ".$_SESSION['CurrentContact_id'].";";
		echo $sql; exit;
		/*
		$res = mysql_query($sql);
		$row_set = mysql_fetch_assoc($res);
		$tmp = $_FILES["Filedata"]["tmp_name"];
		$file = 'ID_'.date('YmdHsi').'_'.$row_set['SurName'].'_'.$row_set['FirstName'].'_'.$_SESSION['app_id'].'.'.$fileParts['extension'];
		//$file_path = $_SERVER['DOCUMENT_ROOT']."/draft/MC_DATA/IDCheck/".$file;
		$file_path = $targetFolder."/IDCheck/".$file;
		$store_file_path = "MC_DATA/IDCheck/".$file;			
		
		
	
			//move_uploaded_file($tempFile,$file_path);
			if(move_uploaded_file($_FILES["Filedata"]["tmp_name"], $file_path))
			{
				$sql = "INSERT INTO crm_idcheckhistory(`app_id`,`CurrentContact_id`,`OriginalContact_id`,`CreatedDate`,`IDCheckFile`,`IDCheckFilePath`,`IDCheckNo`,`IDCheckReferNo`,`Createdby`) VALUES('".$_SESSION['app_id']."', '".$_SESSION['CurrentContact_id']."' ,'".$_SESSION['CurrentContact_id']."' ,'".date('Y-m-d H:i:s')."' ,'".$file."', '".$store_file_path."', '0', '0', '".$_SESSION['CurrentContact_id']."')";
				echo $sql; exit;
				mysql_query($sql);
				$IDCheckhistoryID = mysql_insert_id();
				if($IDCheckhistoryID > 0)	
				{
					$sql = "UPDATE sacc_verificationstatus SET idcheck_status = '1' WHERE app_id = ".$_SESSION['app_id'];
					mysql_query($sql);
					
					$action = "IDVerificationUpdate";
					$description = "Client update the ID verification document";
					saveActivityHistory($action, $description);
					
					//echo json_encode(array('Success' => 'Your file has been uploaded successfully'));
					//var_dump($_SESSION);
					echo 'Success';
				}
				else
				{
					if(file_exists($file_path)) 
					{
						unlink($file_path);
					}
					//echo json_encode(array('Failure' => 'Your file has not been uploaded successfully')); 
					echo 'Failure';
				}
			}
			//echo '1';
		/* ********** */
	}
}

if(isset($_POST['type']) && $_POST['type'] == 'payslipcheck')
{	
	$verifyToken = md5('unique_salt' . $_POST['timestamp']);

	if (!empty($_FILES) && $_POST['token'] == $verifyToken) {
		$tempFile = $_FILES['Filedata']['tmp_name'];
		$targetFile = rtrim($targetPath,'/') . '/' . $_FILES['Filedata']['name'];
		
		// Validate the file type
		$fileParts = pathinfo($_FILES['Filedata']['name']);
		
		
		/* ********** */
		//ID2013120101035_2013_Testuser_3.png
		$sql = "SELECT FirstName, SurName FROM crm_contact WHERE ContactID = ".$_SESSION['CurrentContact_id'].";";
		//echo $sql;
		$res = mysql_query($sql);
		$row_set = mysql_fetch_assoc($res);
		$tmp = $_FILES["Filedata"]["tmp_name"];
		$file = 'PS_'.date('YmdHsi').'_'.$row_set['SurName'].'_'.$row_set['FirstName'].'_'.$_SESSION['app_id'].'.'.$fileParts['extension'];
		//$file_path = $_SERVER['DOCUMENT_ROOT']."/draft/MC_DATA/PaySlipCheck/".$file;
		$file_path = $targetFolder."/PaySlipCheck/".$file;
		$store_file_path = "MC_DATA/PaySlipCheck/".$file;			
		/* ********** */
		
		
			//move_uploaded_file($tempFile,$file_path);
			if(move_uploaded_file($_FILES["Filedata"]["tmp_name"], $file_path))
			{
				$sql = "INSERT INTO crm_payslipcheckhistory(`app_id`,`CurrentContact_id`,`OriginalContact_id`,`CreatedDate`,`Createdby`,`PayslipFile`,`PayslipFilePath`,`PayslipNo`) VALUES('".$_SESSION['app_id']."', '".$_SESSION['CurrentContact_id']."' ,'".$_SESSION['CurrentContact_id']."' ,'".date('Y-m-d H:i:s')."' ,'".$_SESSION['CurrentContact_id']."', '".$file."', '".$store_file_path."', '0')";
				mysql_query($sql);
				$payslipCheckhistoryID = mysql_insert_id();
				
				if($payslipCheckhistoryID > 0)	
				{
					$sql = "UPDATE sacc_verificationstatus SET payslip_status = '1' WHERE app_id = ".$_SESSION['app_id'];
					mysql_query($sql);
					$action = "PayslipUpdate";
					$description = "Client update the Payslip document";
					saveActivityHistory($action, $description);
					echo 'Success';
				}
				else
				{
					if(file_exists($file_path))
					{
						unlink($file_path);
					}
					echo "Failure";
					
				}
			}
			//echo '1';
		
	}
}

if(isset($_POST['type']) && $_POST['type'] == 'photoidcheck_attachment')
{	 
	$verifyToken = md5('unique_salt' . $_POST['timestamp']);

	if (!empty($_FILES) && $_POST['token'] == $verifyToken) {
		$tempFile = $_FILES['Filedata']['tmp_name'];
		$targetFile = rtrim($targetPath,'/') . '/' . $_FILES['Filedata']['name'];
		
		// Validate the file type
		$fileParts = pathinfo($_FILES['Filedata']['name']);
		
		
		/* ********** */
		
		$sql = "SELECT FirstName, SurName FROM crm_contact WHERE ContactID = ".$_SESSION['CurrentContact_id'].";";
		//echo $sql;
		$res = mysql_query($sql);
		$row_set = mysql_fetch_assoc($res);
		$tmp = $_FILES["Filedata"]["tmp_name"];
		$file = 'ID_'.date('YmdHsi').'_'.$row_set['SurName'].'_'.$row_set['FirstName'].'_'.$_SESSION['app_id'].'.'.$fileParts['extension'];
		$file_path = $targetFolder."/temp/".$file;
		
		/* ********** */
		
		
			//move_uploaded_file($tempFile,$file_path);
			if(move_uploaded_file($_FILES["Filedata"]["tmp_name"], $file_path))
			{
				$_SESSION['saved_file'][] = $file_path;
				echo "Success";
			}
			else
			{
				echo 'Failure';
			}
			//echo '1';
		
	}
}

if(isset($_POST['type']) && $_POST['type'] == 'payslipcheck_attachment')
{	 
	$verifyToken = md5('unique_salt' . $_POST['timestamp']);

	if (!empty($_FILES) && $_POST['token'] == $verifyToken) {
		$tempFile = $_FILES['Filedata']['tmp_name'];
		$targetPath = $_SERVER['DOCUMENT_ROOT'] . $targetFolder;
		$targetFile = rtrim($targetPath,'/') . '/' . $_FILES['Filedata']['name'];
		
		// Validate the file type
		$fileParts = pathinfo($_FILES['Filedata']['name']);
		
		
		/* ********** */
		
		$sql = "SELECT FirstName, SurName FROM crm_contact WHERE ContactID = ".$_SESSION['CurrentContact_id'].";";
		//echo $sql;
		$res = mysql_query($sql);
		$row_set = mysql_fetch_assoc($res);
		$tmp = $_FILES["Filedata"]["tmp_name"];
		$file = 'PS_'.date('YmdHsi').'_'.$row_set['SurName'].'_'.$row_set['FirstName'].'_'.$_SESSION['app_id'].'.'.$fileParts['extension'];
		$file_path = $targetFolder."/temp/".$file;
		$store_file_path = "MC_DATA/IDCheck/".$file;			
		/* ********** */
		
	
			//move_uploaded_file($tempFile,$file_path);
			if(move_uploaded_file($_FILES["Filedata"]["tmp_name"], $file_path))
			{
				$_SESSION['saved_file'][] = $file_path;
				echo "Success";
			}
			else
			{
				echo 'Failure';
			}
			//echo '1';
		
	}
}


?>